The AI industry is moving at a pace no enterprise security program can reasonably match. New models are released every month. Benchmarks shift. Providers evolve. Today’s leading model will eventually be replaced by something better.

The challenge isn’t that models change. The challenge is ensuring your security operations don’t have to be rebuilt every time they do.

Bricklayer’s Model Provider Management separates the operational layer from the model layer, allowing organizations to adopt the models that best fit their needs without disrupting the agents, workflows, governance, and institutional knowledge they’ve already built.

Operational Architecture vs. Model Architecture

When an organization deploys an agentic security platform, two distinct layers come into play.

The first is the operational architecture: the coordination logic, the multi-agent workflows, the governance architecture, the integrations that connect agents to the tools and data sources that matter. This is where operational capability is built. It is where institutional knowledge accumulates. It is what a security program invests in and builds on over time.

The second layer is the model architecture: the AI model powering the agents. This layer moves on a different rhythm and for different reasons. New models release. Benchmarks shift. A model that performs well for one type of security task may not be the right choice for another. Providers evolve their offerings. Organizations have pre-existing compliance requirements, enterprise licenses, and internal governance policies that shape which models they are even permitted to use. Operational architecture is built over years. Model architecture can change in months.

Many agentic platforms bundle them together by default, tying the operational architecture to a specific model or provider relationship. When they are coupled this way, changes at the model layer create unnecessary disruption at the operational layer. A model your security team has already evaluated and approved through your governance process still requires reconfiguration across deployments that had nothing to do with that decision. Switching models can mean rebuilding infrastructure that was functioning correctly.

The problem is not that models change. They will always change. The problem is when the operational architecture has no way to accommodate that change without being rebuilt around it.

Bricklayer’s approach has always been that the primary value of an agentic security platform lies in how it coordinates agents to do work, not in which model powers them. Bricklayer’s Model Provider Management is the capability that makes that principle operational.

What Model Provider Management Is

Model Provider Management is a new Bricklayer capability that allows organizations to configure, manage, and assign different AI models to different agents across their agentic security environment.

It is accessed through a dedicated providers tab within the Bricklayer platform. From there, administrators can connect models available through Azure OpenAI, AWS Bedrock, OpenAI, and Anthropic, using their existing API credentials to access the models available under each account.

Once a provider is configured, the platform retrieves the available models from that provider. Those models can then be bound to specific agents. Different agents can run on different models. The right model for a specialized threat hunting agent does not have to be the same model running a routine triage workflow.

By default, organizations continue to operate on Bricklayer’s recommended model configurations, maintained and updated based on our ongoing evaluation of what performs best for each type of security task. For organizations that need more control, Model Provider Management provides the mechanism to exercise it.

What Model Provider Management Makes Possible

Use the Models You’ve Already Approved

Many enterprise security teams do not have the freedom to simply adopt a new AI model because it performed well on a benchmark. Internal governance processes require that models be evaluated and approved before they are used in production. Procurement may require that enterprise licenses already in place be utilized before additional spend is authorized. Legal and regulatory requirements in some industries mandate documented validation of any AI system before deployment.

Model Provider Management addresses this directly. Organizations connect through their existing provider API credentials, whether that is an Azure OpenAI account, an OpenAI account, an AWS Bedrock account, or an Anthropic account. The model is approved once through your existing governance process and is then available for assignment across the agentic environment within Bricklayer.

In multi-organization or service provider deployments, a parent organization can configure and publish validated models centrally. Sub-organizations and managed customer tenants see the approved models available for agent assignment in a read-only view. They can assign models to their agents, but validation and onboarding happen once, at the parent level. This eliminates duplicated administrative overhead across subsidiaries, business units, and customer environments, and ensures consistency across the enterprise.

The Right Model for Every Agent

Not all agentic security tasks are the same. The reasoning required to triage a high-volume alert queue is different from the deep analytical work required for a complex threat hunt or a nuanced vulnerability analysis.

AI models have genuine differences in how they perform across these task types. A model optimized for speed and throughput may be the right choice for routine enrichment and classification. A model with stronger reasoning capabilities may be better suited for investigation procedures that require drawing connections across disparate data sources. A model that excels at synthesis and structured output may be the better choice for reporting, where findings need to be clearly communicated to stakeholders.

With Model Provider Management, organizations can match models to the tasks where they perform best. These are decisions that can now be made deliberately, at the agent level, rather than applied uniformly across an entire deployment. This also means organizations can selectively adopt newer, more capable models where it matters most, without waiting until they are ready to overhaul their entire deployment.

Your Operational Investment Stays Protected

The AI model landscape is advancing quickly. What is at the frontier today will be surpassed. New providers will emerge. Existing providers will release meaningfully better versions. The determination of which model best serves a given task will shift repeatedly over the course of a security program.

Security operations teams invest significant effort in the operational layer: the agent configurations, the multi-agent procedures, the integration pipelines, the governance structures, the institutional knowledge about what works. Model Provider Management ensures that investment compounds rather than gets rebuilt. When a better model becomes available, it can be evaluated, approved through existing governance processes, and assigned to relevant agents without touching anything else. The workflows stay intact. The operational knowledge accumulated over time continues to grow.

Organizations stay current on the model layer without paying for it with disruption at the operational layer.

Model Provider Management in the Platform

Adding and Managing Providers

The providers tab is the central interface for managing all model configurations. Administrators can add new providers by supplying their organization’s API credentials, base URLs, and any required configuration details specific to the provider. Once the credentials are submitted, the platform authenticates against the provider and retrieves the full list of models available under that account. Administrators then select which models to make available within Bricklayer and publish them for use.

Organizations bring their existing credentials rather than provisioning new ones. The models they have already evaluated and cleared through internal governance are the ones that appear for selection. Nothing new needs to be procured or approved outside of Bricklayer’s configuration process.

Centralized Model Governance Across Organizations

For enterprises and service providers operating across multiple organizations or customer environments, model configuration does not need to be replicated in each environment. Administrators at the parent organization configure models once and publish them centrally from the agent client configuration area. Sub-organizations and customer tenants receive a read-only view of the models the parent organization has made available. They can see which models are onboarded and approved, expand any entry to review the specific model variants available, and select from those options when assigning models to their agents.

Validation and onboarding responsibility stays with the organization best positioned to perform it, while every environment in the hierarchy benefits from the work done once at the top.

Binding Models to Agents

Once models are published and available, they can be assigned to individual agents. This is done at the agent configuration level, giving administrators precise control over which model powers each agent in their environment. An agent running deep-dive incident investigations can be assigned a model with stronger multi-step reasoning. An agent handling high-volume, lower-complexity triage can be assigned a model optimized for throughput. Different parts of the security operation can run on the models best suited to the work they perform.

When the model landscape shifts, whether a provider releases a better-performing version or the security team completes evaluation of a newly approved model, the binding can be updated at the agent level without touching the workflows, procedures, or operational logic that agent is part of. The operational layer stays intact. Only the model assignment changes.

Available Now

Model Provider Management is available in the current Bricklayer release with support for Azure OpenAI, AWS Bedrock, OpenAI, and Anthropic. Organizations continue to operate on Bricklayer’s default model configurations unless they choose to configure their own. To see how Bricklayer’s Model Provider Management fits into your environment, schedule a demo.